Karel Srot

Results 60 comments of Karel Srot

Hi @annaet, basically I wanted to go with the patch above, which fixed my use case but may not work for other rare cases. In the PR I wanted to...

Adding a screenshot of what I mean in particular. Maybe there could be also a date etc. ![image](https://user-images.githubusercontent.com/16130993/195653751-5cfabbea-fd4e-494a-9632-643a50deb3cb.png)

Hello, I think the test failures on C8S could be caused be a problem described here https://stackoverflow.com/questions/59101121/type-hint-for-a-dict-gives-typeerror-type-object-is-not-subscriptable C8S has Python 3.6.8 where (to my understanding) `record_object: dict` won't work.

We have a reproducer available in https://github.com/RedHat-SP-Security/keylime-tests/pull/175 so one way to test it could be updating `tmt` test plans to point to that PR repo and branch by modifying `url`...

> The only time I have encountered something that hangs using the tss-esapi crate was when I had two different process trying to access the TPM simultaneously without using a...

Hi @stefanberger , I am sorry for a delayed response. I believe that the actual problem was that my issuercert.pem file was corrupted. At least I seem to be able...

It seems this issue is still not fixed upstream. In Fedora this is addressed with https://src.fedoraproject.org/fork/ksrot/rpms/keylime/blob/rawhide/f/keylime.spec#_248 @THS-on Any preference about the upstream fix?

> The systemd way is probably the most distribution agnostic way to fix this. Can you tell which services are using this directory?

It seems that sharing one directory by multiple services is not good idea https://github.com/systemd/systemd/issues/5394

So we would also need a new service file for IMA emulator.